Information Infrastructure, Insight

@textonline chat OR CALL

01483 520 200

Citrix Environment Security Assessment

Since the first shipping of Multi-User in 1991, Citrix has grown in capability and usage as organisations take advantage of the many benefits of thin client technology for fat application deployments. By reducing administrative costs, improving control over the user environment and helping organisations conform to any number of legislative and regulatory standards, Citrix is well-known and extensively used in many organisations.

Citrix security

MTI Citrix Environment Security Assessment: Overview

MTI’s experience of testing over 100 Citrix installations has proved in every single test conducted that it is possible to abuse any number of misconfigurations, lockdown oversights, published applications or other software vulnerabilities to break out of the confined environment a user is placed into and access parts of the host or network that a citrix user was never intended to have access to.

Put simply, implementing Citrix without fully understanding how to adequately lockdown the environment can lead to high impact compromises of both the Citrix host and the network it resides on, MTI can help with Citrix Security.

The range of issues identified during assessments includes:

  • Gaining read/write access to sensitive financial and trading data (often resulting in a breach of PCI rules)
  • Gaining read/write access to restricted drives (breaching basic security principles)
  • Gaining access to administrator accounts and user passwords (breaching basic security principles)
  • Gaining full access to customer & business databases (breaching DPA & PCI requirements amongst others)
  • Ability to send any electronic information out of the business, avoiding content monitoring software (allowing simple data theft)
  • Ability to download arbitrary files to the host and install and run Trojan and backdoor hacking tools

We have seen that even for businesses who have invested a considerable amount of time, thought and attention in securing the Citrix platform, high risk vulnerabilities can still be found. As a result we feel confident to state that simply working from hardening guides is not sufficient to secure the Citrix /Windows environments. However, merely applying more and more mitigation measures can often target expenditure in the wrong areas and only address the symptoms, not the causes. Testing is therefore essential to identify the real issues and select the appropriate controls.

Next Steps...

If you would like more information regarding our Citrix Environment Security Assessment, please contact the MTI penetration testing team to discuss your requirements.

@text Request Call Back
@text Request Pricing
Document Downloads

Citrix Environment Security Review Whitepaper »

  • CHECK Green Light Member

    CHECK Green Light Member

  • Member of the Council of Registered Ethical Security Testers

    Member of the Council of Registered Ethical Security Testers

Follow MTI on TwitterFind us on LinkedInView our You Tube channel

Join us, @451Research, #EMC, #Cisco & #VMware at the @TheNMMUK and discover a new way of delivering IT efficiency.

  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
  • [Title]
Seminar: MTI VSPEX Event at The Aberdeen Maritime Museum
Wed May 29 2013 - 1:30 PM
Location: The Aberdeen Maritime Museum

Seminar: MTI VSPEX Event at The National Motorcycle Museum with 451 Group
Thu Jun 06 2013 - 9:30 AM
Location: The National Motorcycle Museum

See all Events & Shows